Sceawere

Vulnerability Detail

CVE-2026-73997UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Starter Templates Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Nexcess
Product
Starter Templates by Kadence WP
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T15:17:08.747Z",
  "pubdate": "2026-08-18T15:17:08.747Z",
  "executiveSummary": "An unauthenticated Denial of Service (DoS) vulnerability has been identified in the Starter Templates by Kadence WP plugin for versions <= 2.3.3. This vulnerability allows remote, unauthenticated threat actors to disrupt service availability by exhausting system resources or causing application crashes on targeted WordPress installations running the vulnerable software.\nThe flaw stems from improper handling of requests within the plugin, enabling attackers with zero privileges and no prior authentication to trigger resource-intensive operations over the network. Successful exploitation requires no specialized access, allowing low-complexity attacks that can be automated via standard HTTP requests.\nThe primary impact of this vulnerability is availability degradation, which can render the affected website unresponsive to legitimate users, disrupt business operations, and potentially lead to cascading failures on resource-constrained hosting environments. Given the unauthenticated nature and remote attack vector, the risk profile is significant for exposed instances running vulnerable versions.\nMitigation requires immediate administrative action to update the affected plugin beyond the vulnerable version threshold, alongside the implementation of standard web application firewall rules to filter malicious request patterns.",
  "technicalDetails": "The vulnerability resides in the Starter Templates by Kadence WP plugin <= 2.3.3, specifically within the request-handling components responsible for processing incoming client payloads related to template importing or retrieval.\nThe root cause of the issue is inadequate input validation and resource management deficiencies. When an unauthenticated remote attacker sends a maliciously crafted HTTP request to the vulnerable endpoint, the application fails to adequately throttle, bound, or sanitize the incoming parameters. This results in excessive CPU consumption, memory exhaustion, or unhandled exceptions that disrupt the PHP execution thread.\nThe attack flow proceeds as follows: 1) The unauthenticated attacker identifies the exposed endpoint associated with the Starter Templates by Kadence WP plugin. 2) The attacker crafts a specific HTTP request designed to trigger the vulnerable code path without requiring session tokens, cookies, or user credentials. 3) The target web server receives the request and forwards it to the WordPress application layer. 4) The vulnerable component parses the payload and initiates resource-intensive operations or triggers an error state. 5) The server resources are rapidly depleted or the worker process terminates abnormally. 6) Subsequent legitimate requests fail or time out, resulting in a complete Denial of Service condition for the web application.\nBecause the attack vector is network-exposed and requires no authentication or privileges, any remote entity capable of reaching the WordPress site can execute the payload. The lack of cryptographic verification or access control checks on the vulnerable functions enables this abuse. Post-exploitation impact is strictly tied to availability, as arbitrary code execution or data exfiltration is not natively indicated by the DoS vector, though prolonged application unavailability can severely impact site integrity and user trust."
}
CVE-2026-73997: Starter Templates Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere